You are here: hacking technology > hacker course > Content
Hot Articles
Recommend Articles
New Articles
The random combined command achieves exempts kills(3)
  Add date: 07/15/2008   Publishing date: 07/15/2008   Hits: 7
Total 5 pages, Current page:3, Jump to page:
 
push esp
pop ebp
pop esp
jmp original entrypoint address
13. the most new section multi-purpose exempts kills the colored instruction:
push ebp
push esp
pop ebp
add esp,-0C
add esp,0C
push eax
jmp entrance

14. exempts kills the colored instruction
push ebp
mov ebp, esp
add esp,-0C
add esp,0C
push eax
mov eax, entry point address
jmp eax
nop
15.
jmp alters to: Jg (is bigger than shift), JL (is smaller than shift)
Or alters to: jb (is smaller than shift), jnb (is bigger than or is equal to shift)
16. writes the Caba flower instruction to jump do not jump directly with jmp, otherwise, must kill directly
jmp ---Is killed directly
Altering to
jb
jnb
Or alters to:
push entry point address
retn
Or alters to:
mov eax, entry point address
jmp eax

17.1 sections exempt kill Caba the colored instruction:
push ebx
push ebx
pop ebx
pop ebx
add esp,1
add esp,-1
push entry point address
retn
*****************************************************************
Exempts kills the experience:
1. adds the area, after adding the flower, then encrypts, may quite easy Caba----If encryption tool vmprotect
Has peeled off the shell wooden horse---Adds the flowered instruction, or adds the area to add the flower---Encryption---Adds the compression shell---Adds the area to add the flower again to refer to
Making
2. solely Canada exempted kills the flowered instruction already not to be able Caba, after certainly must coordinate Canada exempted the flower, to add the compression shell, could get up exempts kills Caba the effect.
vmprotect encryption----Adds the flower again-----But Caba:
3. adds the double-decked flowered instruction to exempt kills the law----Exempts Caba
4. encryption---007 memories exempt----Compression ---Exempts Caba or the memory.
5. double-decked encrypts (maskpE)---Compression ----But Caba.
6.maskpe encryption---asppack adds the shell ---Changes the entrypoint to add 1---But Caba
7. encrypts maskpe----Adds the flower or adds the area to add the flower (with tool)-----Adds the compression shell---Exempts Caba
8. the Beidou may pressurize to the black against pigeon two times, recompression other compression shell. Reaches exempts kills.
9. has added the Beidou shell, on to pulls boils the mouse 50 many times, some section of spatial codes, may add the flower, the shift.
10. topping shift entrypoint---Adds the flower----Encrypts (vmprotect) ----Canada compresses == to kill the poison
11. copes with Caba, Canada exempts kills the colored instruction. The colored instruction looks up to the auspicious star catalog surface kills general invalid, generally Canadian compression shell.
12. copes with the auspicious star catalog surface: Somewhat black soft, adds the area, after adding the flower, is killed by the auspicious star catalog surface, may like this: Has pressurized the first auspicious star catalog surface, however add-on exempts kills the flowered instruction, crosses Caba.

13. auspicious star catalog surface Zha Sha method:

 

Other pages: : <<Prev * 1 * 2 * 3 * 4 * 5 * Next>>
Prev:The bored Css cross station hangs the horse Next:The hacker teaches you anything is the SQL injection method attack

Comment:

Category: Home > hacker course